We are a Full-Service NIST 800-171 R2 and CMMC Implementation Company


CMMC Pause Explained;Date August 12, 2026;

2, 2026

DCS Opinion on the pause mandated by the DoW of CMMC.

 

DFARS clause 252.204-7012 does not mention self-assessments anywhere. Yet the Executive Order dated July 13, 2026, states as follows;

“In alignment with Pillar 3, the DoW Chief Information Officer (CIO) has paused the rollout of the Cybersecurity Maturity Model Certification (CMMC) Program and suspended CMMC Phase 2 implementation.”

 

  • “Immediate Relief on Current Solicitations and Contracts: If the original requirements package included a CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC) requirement, Program Managers and requiring activities must initiate amendments to active solicitations. They will provide an amended requirements document explicitly removing those requirements to the cognizant contracting officer or agreements officer, as applicable. The contracting officer or agreements officer must issue a corresponding solicitation amendment as soon as practicable. For existing contracts or agreements that already contain these requirements, contracting officers and agreements officers are directed to remove them via modification prior to the exercise of the next option period or during the next scheduled administrative modification.

 

  • Suspension of Waiver Procedures: Program Managers and requiring activities must continue to identify information security requirements associated with a planned contract effort. Due to suspension of the CMMC Phase II implementation and the ability for program managers and requiring activities to select any CMMC requirements that would require CMMC Level 2 (3CPAO) or CMMC Level 3 (DIBCAC), no waivers shall be granted during the review of the program. This directive is effective immediately. Further guidance will be promulgated at the conclusion of the CIO’s 60-day review.”

 

 

DFARS clause 252.204-7020, which dictated self-assessments has been renumbered to 252.240-7997 which is part of FAR part 40.

That does not include any self-assessments as third party assessments were required in the CMMC program which has been paused. This change in the DFARS is why  so many SMEs stated there was no need for self-assessments.  That was before the pause.

 

 

 

Pieces from Governmentcontractslaw.com posting;

 

https://www.governmentcontractslaw.com/2026/07/dod-suspends-cmmc-phase-2-what-happened-what-it-means-and-what-nobody-is-telling-you/With no third-party assessor, whose signature now carries the legal risk? Yours.

  • Does your prime contract care what the Pentagon announced? No, and it still binds you.
  • That gap assessment in your files documenting your shortfalls? It did not evaporate.
  • Why a memo instead of a regulation? Because a memo can be reversed just as fast.

Key Takeaways

  • DoD suspended CMMC Phase 2 and froze future implementation phases, but it did not repeal the CMMC Program rule or amend the DFARS.
  • This is a policy pause, not a regulatory change. Until a class deviation, DFARS rule, or amendment to 32 C.F.R. Part 170 issues, the existing legal framework remains in effect.
  • Contracts—not headlines—control. Existing CMMC clauses, DFARS cybersecurity requirements, and prime contractor flowdowns remain enforceable unless and until they are modified.
  • Self-attestation now carries greater legal risk. Annual SPRS affirmations remain required, and DOJ’s Civil Cyber-Fraud Initiative continues to target false cybersecurity certifications.
  • Government contractors handling CUI should continue implementing NIST SP 800-171, maintain accurate SPRS records, and proceed with compliance efforts unless a deliberate business decision supports a different course.
  • Treat this as a pause, not a repeal. Watch for the August 14 RFI, the Task Force recommendations, and any class deviation or DFARS rulemaking that actually changes the law.

This Is a Memo, Not a Rule

The suspension was affected by two memorandum released July 13 under publication case 26-P-1023—a policy memorandum from the DoD CIO and an implementation memorandum from the undersecretary of defense for acquisition and sustainment—not a rule. No Federal Register document has been issued, 32 C.F.R. Part 170 is unamended, and no DFARS class deviation has been published. The CMMC Program rule and DFARS 252.204-7021 remain in force exactly as written. 

 

So, for now, it is the opinion of Defense Cyber Solutions that self-assessments for Level 1 or Level 2 are to be continued. The safety portion of having the score assessed by a third party is removed and it is now the company’s responsibility to ensure the score is accurate. False Claims Act will be a priority for the DoW. Experience has shown that perfect scores attract the attention of DIBCAC and sometimes cause government audits. Previously most of the scores were incorrect and the government let it slide, not any longer.


 


 CMMC

We can assist from start to finish!




Cyber AB trained and certified (CCA) CMMC Certified Assessor and (RP) Registered Practitioner Professionals Assisting Small and Medium Businesses with NIST 800-171 and (CMMC) Cybersecurity Maturity Model Certification process from start to finish. We have been helping companies get NIST 800-171 compliant since 2016.



Cyber AB CMMC Certification

Cyber AB CMMC Certification

CMMC-AB Provisional Assessor

CMMC-AB Provisional Assessor

WID Women in Defense

WID Women in Defense

Arsenal of Democracy Chapter

Arsenal of Democracy Chapter


Services


Policies & Procedures


We have templates where you only need to fill in certain information so the Policy matches your processes. Helps a company pick up over 110 points in 3-5 hours.

SSP


Do you have an SSP? Do you need one? If your SSP is ready for an assessment? We can assess if you are ready for your CMMC assessment and/or help finish what you need. From start to finish.

Training


We can conduct your training(s) and leave you with templates so you can conduct your future trainings. All training is custom prepared to your SSP. Along with training, the focus will always be on FCI and CUI at your organization. We also have links to videos if you prefer something quick and high level overview instead of custom.

GAP Analysis


Let our team evaluate your readiness for Level 1 or Level 2 certification.

Contact Us

You have questions, we have answers. Contact us anytime for general inquiry questions relating to the latest information from CyberAB and the DoD. Need help with a specific practice or just trying to get a handle on the entire CMMC process? Send us a message!

DON'T MISS A THING

Be the first to hear about NIST 800-171R2 changes and updates!

We promise to only send you the most up to date information. No Solicitation. Your information will be protected from third parties.

GET A FREE CONSULTATION

We strive to be in constant communication with our customers until the job is done. We look forward to serving you!

Contact Us